Unauthenticated Management API Exposure in Known's Software by Known's Dev
CVE-2026-86543
9.3CRITICAL
What is CVE-2026-86543?
Versions of Known's Software before 0.30.0 expose the management API without any authentication, allowing unauthorized access to critical endpoints. By default, fresh installations permit unauthenticated access to the /api/tunnel/start endpoint across all network interfaces. This vulnerability enables attackers to provision a public tunnel and could potentially republish the management API at a publicly accessible address, significantly increasing the risk of data exposure and unauthorized control.
Affected Version(s)
knowns 0 < 0.30.0
knowns 0.30.0
